For years, China’s cross-border data transfer regime was long on rules but short on consequences. Companies—both foreign and domestic—were given a relatively extended period to understand the requirements, formulate suitable strategies, and implement compliance measures. Recent enforcement actions led by the Cyberspace Administration of China (CAC), the country’s data regulator, suggest that the education phase

Continue Reading CHINA: China’s Data Regulator Means Business – The Education Phase Is Over

The protection of children online, including the safeguarding of their personal data, has emerged as a key regulatory focus in the UK, with the Government facing sustained pressure to address concerns about children’s safety online.[1] Recent developments have added further momentum – in particular, Australia’s recent prohibition on social media use by under-16s has

Continue Reading UK: Protecting Children Online – A Changing Regulatory Landscape

The Senate Commerce Committee held an oversight hearing of the Federal Trade Commission (FTC) on April 15, 2026, its first in six years. Chairman Andrew Ferguson testified that the FTC policy focus will be combating hidden fees and misleading pricing practices by avoiding misleading representations about pricing and clearly disclosing total cost up front.  

The

Continue Reading U.S.: FTC Oversight Hearing

On March 3, 2026, the California Privacy Protection Agency (CalPrivacy) announced a settlement with PlayOn Sports (formerly 2080 Media, Inc.), imposing a $1.1 million administrative fine and sweeping compliance obligations. Reached in January, the settlement marks a significant escalation in state privacy enforcement and is the first CalPrivacy action to address privacy violations involving students

Continue Reading U.S.: California’s PlayOn Enforcement: A New Chapter in Children’s Data Privacy

The FTC just released a policy statement regarding enforcement activities related to COPPA, which can be found at this link.

According to Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection, age verification technologies are important child-protective technologies, and this policy statement “…incentivizes operators to use these innovative tools, empowering parents to protect

Continue Reading U.S.: FTC Issues COPPA Policy Statement to Incentivize the Use of Age Verification Technologies to Protect Children Online

The Cyberspace Administration of China (“CAC“) has recently published the Administrative Measures for Network Security Incident Reporting (“Measures“), which provide further guidance on when and how to report network security incidents under existing laws such as the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law. The Measures

Continue Reading CHINA: new stricter and 4-hour data breach reporting requirements for certain incidents

Since the full enforcement of Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) in June 2022, the Personal Data Protection Committee (“PDPC”) has moved decisively from awareness-building to active enforcement. The transition emerged in 2024 when a leading e-commerce company was fined THB 7 million for breaching the law.

In

Continue Reading Thailand: PDPA Crackdown 2025: Are You Next? – Major Fines and Lessons from Thailand’s Latest Enforcement

In a decision issued on 18 July 2025 against Google LLC, the Personal Data Protection Office (PDPO) has affirmed that the data protection compliance obligations under Ugandan law apply to all entities that handle the personal data of Ugandan citizens, regardless of where they are based.

The office has also clarified that a

Continue Reading Uganda: Data protection Regulator Clarifies Compliance Requirements for Offshore Entities

The Italian Data Protection Authority (Garante) has fined a company EUR 420,000 for violating privacy laws in the workplace. The decision focuses on the employer’s use of content from Facebook, WhatsApp, and Messenger— shared from the employee’s personal accounts—for disciplinary purposes.

This ruling will have serious repercussions for any employer operating in Italy, especially those

Continue Reading Italy: Garante issues fine for use of employee’s private chats in disciplinary actions